Home » Duqu: Is It the Next Stuxnet?
Duqu: Is It the Next Stuxnet?
ControlDesign.com
11/17/2011
The Stuxnet virus has received a great deal of attention over the past few years because it brought into reality what had previously been considered on a hypothetical basis: a sophisticated cyber attack on a critical infrastructure. Though we have debated the level of hype surrounding the Stuxnet virus, considering that it specifically targeted Iran's nuclear program, industry experts have warned that this particular malware was just the beginning, and industrial networks need to be prepared for similar attacks. Now another piece of malware has been found operating in systems in Europe.
Symantec (www.symantec.com), receiving the news from a research lab in mid-October, confirmed that the new threat—called Duqu because it creates files with the file name prefix "~DQ"—is a precursor to another Stuxnet-like attack. Duqu appears to have been created since the last Stuxnet file was recovered, according to Symantec, and its structure and design philosophy are very similar to Stuxnet. Parts of Duqu's source code are nearly identical to Stuxnet. Whether that means Duqu was created by the same group that created Stuxnet or by somebody who gained access to the Stuxnet code is unknown, but regardless the new virus appears to have a different purpose.
"Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party," Eric Chien wrote in Symantec's official blog. "The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility."
Unlike Stuxnet, Duqu does not contain any code related to industrial control systems, according to Symantec, which reported that Duqu is primarily a remote access Trojan (RAT) and does not self-replicate. "Our telemetry shows the threat was highly targeted toward a limited number of organizations for their specific assets," Chien wrote. "However, it's possible that other attacks are being conducted against other organizations in a similar manner with currently undetected variants."
Duqu executables were designed to capture information such as keystrokes and system information, Symantec said. The attackers were searching for assets that could be used in a future attack. Although it would appear that they did not retrieve any sensitive data, details are not available in all cases. Two variants were recovered. The first recording of one of the binaries was Sept. 1, 2011. "However, based on file compile times, attacks using these variants may have been conducted as early as December 2010," Chien explained.
Duqu has been less widespread than Stuxnet, and was designed to eliminate itself after 36 days of running in a system. The threat uses a custom command-and-control protocol, Symantec said, primarily downloading or uploading what appear to be jpeg files. It then also transfers additional data for exfiltration.
Although Stuxnet was designed to sabotage an industrial control system, Duqu is geared toward general remote access capabilities. "The attackers intend to use this capability to gather intelligence from a private entity to aid future attacks on a third party," Chien wrote. "While suspected, no similar precursor files have been recovered that predate the Stuxnet attacks."
Symantec said it was alerted to the Stuxnet-like sample by "a research lab with strong international connections." Although the organization provided a detailed report, it has remained anonymous. "As we are in academia, we have limited resources to analyze malware behavior," the original researchers commented in their report. "That means we leave several questions for further investigation."
More News:
-
05/16/2012
ABB Completes Acquisition of Thomas & Betts
With the Completion of Its Acquisition of Thomas & Betts, ABB's Largest Market Is Now in the U.S., With About $6.6 Billion in Annual Revenue and 19,000 Employees
-
05/15/2012
Eaton Gives Back to Cleveland Community
Eaton Donates More Than $700,000 to Support Education, the Arts, and Minority Development in the Greater Cleveland Area
-
05/14/2012
Tri-Tronics Announces Acquisition of Photocraft
Tri-Tronics Co., a Tampa, Fla. designer and manufacturer of photoelectric sensors, fiber optic light guides and controls primarily for packaging machines, has acquired Photocraft Inc.
-
05/10/2012
Profinet Gathers Momentum as Single Manufacturing Network
OEMs, Users and Automation Suppliers Voice Support for Top-to-Bottom Ethernet Solution
-
05/10/2012
Drives Push Industrial Networking Expansion
New Connected Nodes Are Growing Quickly for Servo and Inverter Drives, Pushing Strong Growth of Fieldbus- and Ethernet-Based Industrial Networking
-
05/10/2012
Renishaw Declares Acquisition of R&R Sales and Engineering
Renishaw's Merge Supports Growing Focus on Metrology System Sales
-
05/10/2012
10 Years On, CC-Link Marks U.S. Inroads
Celebrating the 10-Year Anniversary of Its Establishment in North America, the CC-Link Partner Assn. Points to Increased Membership and Accomplishments
-
05/07/2012
15 Years of Control Design: Flashback 1997-2012 - May
May Highlights Included Several Advances in Science, Technology and Automation
-
05/04/2012
Onboard PAC Helps Pilot to Deepest Ocean
Snap PAC Takes its Capabilities Beyond the Plant Floor to the Sea Floor
-
05/03/2012
Sensors Expo Expands Conference Sessions
2012 Sensors Expo & Conference returns to the Donald E. Stephens Convention Center in Rosemont, Ill., June 6-7
- All news »
Sponsored Links
Control Design Digital Edition
Access the entire print issue on-line and be notified each month via e-mail when your new issue is ready for you. Subscribe today.
- Featured White Papers

Print page